NGINX Plus and NGINX Open Source HTTP/3 QUIC Denial-of-Service Vulnerability

Vulnerability

A denial-of-service vulnerability has been identified in NGINX Plus and NGINX Open Source versions 1.25.0 prior to 1.25.4, as well as in NGINX Plus R3x. When the experimental HTTP/3 QUIC module is enabled, undisclosed requests can lead to the termination of NGINX worker processes. This disruption causes a temporary outage as the NGINX process restarts.

Impact

Exploitation of this vulnerability causes NGINX worker processes to crash, leading to a denial-of-service condition where traffic is disrupted until the processes are restarted.

Remediation

Users can upgrade to NGINX versions 1.25.4 or 1.27.0. For NGINX Plus, the latest version is recommended. If an immediate upgrade is not possible, the HTTP/3 module can be disabled in the NGINX configuration.

Added: Mar 11, 2026, 7:03 PM
Updated: Mar 11, 2026, 7:03 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
7.4
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.